CVE-2026-72761 PUBLISHED

Webhook SSRF guard bypassed by IPv6 transition addresses (NAT64/6to4/Teredo pass is_global check) in vulnerability-lookup

Assigner: CIRCL
Reserved: 10.08.2026 Published: 10.08.2026 Updated: 10.08.2026

The webhook URL validator in website/notifications/webhooks.py uses ip.is_global to reject non-public addresses after DNS resolution. IPv6 transition addresses (NAT64 64:ff9b::/96, 6to4 2002::/16, Teredo 2001:0000::/32) are classified as globally routable by IANA, so is_global returns True even when the embedded IPv4 targets a private, loopback, or cloud metadata destination. An attacker can register a webhook pointing at a hostname that resolves to a transition address to bypass the SSRF guard and exfiltrate vulnerability data to an internal endpoint.

The vulnerability was introduced on a non-release version. The fix was already done on HEAD. It only affects

organisation running the HEAD.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor vulnerability-lookup
Product vulnerability-lookup
Versions Default: unaffected
  • unaffected from 0 to 5.5.0 (incl.)

Credits

  • tonghuaroot finder
  • Cedric Bonhomme remediation developer

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE

Impacts

  • CAPEC-664 Server Side Request Forgery